CVE-2024-25974

The Frentix GmbH OpenOlat LMS is affected by stored a Cross-Site Scripting (XSS) vulnerability. It is possible to upload files within the Media Center of OpenOlat version 18.1.5 (or lower) as an authenticated user without any other rights. Although the filetypes are limited, an SVG image containing an XSS payload can be uploaded. After a successful upload the file can be shared with groups of users (including admins) who can be attacked with the JavaScript payload.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2024-02-20 08:15

Updated : 2024-02-21 07:15


NVD link : CVE-2024-25974

Mitre link : CVE-2024-25974

CVE.ORG link : CVE-2024-25974


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation